Technical Information
- [<HKLM>\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] 'Remote Task Certificate Link-Layer Thread Extender' = '<SYSTEM32>\sbrwqfgmcm.exe'
- [<HKLM>\SYSTEM\ControlSet001\Services\AuthIP Remote Auto Computer] 'Start' = '00000002'
- Windows Security Center
- '<SYSTEM32>\penueklx.exe' "<SYSTEM32>\sbrwqfgmcm.exe"
- '%WINDIR%\Temp\fcqusax3fminbh.exe' -r 50343 tcp
- '%TEMP%\fcqusax3ccwnbhizfuotvb.exe'
- '<SYSTEM32>\sbrwqfgmcm.exe'
- <SYSTEM32>\clwshjounaqb\run
- <SYSTEM32>\clwshjounaqb\rng
- <SYSTEM32>\clwshjounaqb\cfg
- <SYSTEM32>\clwshjounaqb\por
- %WINDIR%\Temp\fcqusax3fminbh.exe
- %TEMP%\fcqusax3ccwnbhizfuotvb.exe
- <SYSTEM32>\clwshjounaqb\tst
- <SYSTEM32>\clwshjounaqb\etc
- <SYSTEM32>\penueklx.exe
- <SYSTEM32>\sbrwqfgmcm.exe
- <SYSTEM32>\penueklx.exe
- <SYSTEM32>\sbrwqfgmcm.exe
- %WINDIR%\Temp\fcqusax3fminbh.exe
- %TEMP%\fcqusax3ccwnbhizfuotvb.exe
- <DRIVERS>\etc\hosts
- 'we#####aythirteen.net':80
- 'se####irteen.net':80
- 'we####dayhurry.net':80
- 'se###urry.net':80
- 'we####dayhope.net':80
- 'se###ope.net':80
- 'we####dayleft.net':80
- 'se###eft.net':80
- 'dr###hope.net':80
- 'dr###hurry.net':80
- 'na####irteen.net':80
- 'fi###wild.net':80
- 'na###urry.net':80
- 'dr###left.net':80
- 'na###ope.net':80
- 'dr####hirteen.net':80
- 'na###eft.net':80
- 'st###march.net':80
- 'ta###fruit.net':80
- 'st###hurry.net':80
- 'we####irteen.net':80
- 'fr###secas.com':80
- 'do####n4guia.com':80
- 'da###ekilai.com':80
- 'la###onea.com':80
- 'we###urry.net':80
- 'fo####hirteen.net':80
- 'af####hirteen.net':80
- 'fo###hurry.net':80
- 'af###hurry.net':80
- 'fo###hope.net':80
- 'af###hope.net':80
- 'fo###left.net':80
- 'af###left.net':80
- we#####aythirteen.net/forum/search.php?me#########################################
- se####irteen.net/forum/search.php?me#########################################
- we####dayhurry.net/forum/search.php?me#########################################
- se###urry.net/forum/search.php?me#########################################
- we####dayhope.net/forum/search.php?me#########################################
- se###ope.net/forum/search.php?me#########################################
- we####dayleft.net/forum/search.php?me#########################################
- se###eft.net/forum/search.php?me#########################################
- dr###hope.net/forum/search.php?me#########################################
- dr###hurry.net/forum/search.php?me#########################################
- na####irteen.net/forum/search.php?me#########################################
- fi###wild.net/forum/search.php?me#########################################
- na###urry.net/forum/search.php?me#########################################
- dr###left.net/forum/search.php?me#########################################
- na###ope.net/forum/search.php?me#########################################
- dr####hirteen.net/forum/search.php?me#########################################
- na###eft.net/forum/search.php?me#########################################
- st###march.net/forum/search.php?me#########################################
- ta###fruit.net/forum/search.php?me#########################################
- st###hurry.net/forum/search.php?me#########################################
- we####irteen.net/forum/search.php?me#########################################
- fr###secas.com/forum/search.php?me#########################################
- do####n4guia.com/forum/search.php?me#########################################
- da###ekilai.com/forum/search.php?me#########################################
- la###onea.com/forum/search.php?me#########################################
- we###urry.net/forum/search.php?me#########################################
- fo####hirteen.net/forum/search.php?me#########################################
- af####hirteen.net/forum/search.php?me#########################################
- fo###hurry.net/forum/search.php?me#########################################
- af###hurry.net/forum/search.php?me#########################################
- fo###hope.net/forum/search.php?me#########################################
- af###hope.net/forum/search.php?me#########################################
- fo###left.net/forum/search.php?me#########################################
- af###left.net/forum/search.php?me#########################################
- DNS ASK se###urry.net
- DNS ASK we#####aythirteen.net
- DNS ASK dr###hope.net
- DNS ASK we####dayhurry.net
- DNS ASK se####irteen.net
- DNS ASK we####dayhope.net
- DNS ASK se###ope.net
- DNS ASK we####dayleft.net
- DNS ASK se###eft.net
- DNS ASK na###urry.net
- DNS ASK dr###hurry.net
- DNS ASK qu###wild.net
- DNS ASK fi###wild.net
- DNS ASK na####irteen.net
- DNS ASK dr###left.net
- DNS ASK na###ope.net
- DNS ASK dr####hirteen.net
- DNS ASK na###eft.net
- DNS ASK st###march.net
- DNS ASK ta###fruit.net
- DNS ASK st###hurry.net
- DNS ASK we####irteen.net
- DNS ASK fr###secas.com
- DNS ASK do####n4guia.com
- DNS ASK da###ekilai.com
- DNS ASK la###onea.com
- DNS ASK we###urry.net
- DNS ASK fo####hirteen.net
- DNS ASK af####hirteen.net
- DNS ASK fo###hurry.net
- DNS ASK af###hurry.net
- DNS ASK fo###hope.net
- DNS ASK af###hope.net
- DNS ASK fo###left.net
- DNS ASK af###left.net
- '23#.#55.255.250':1900